I made a sandbox to productively work with agents while restricting files they can read and write: https://github.com/wrr/drop